Cybersecurity News

Filters
Tag
Reset

Filtered by tag: azure × Clear

How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

Researchers tracked a large automated password-spraying campaign targeting Azure CLI that exploited OAuth's Resource Owner Password Credentials grant, a deprecated flow still supported by many systems. Attackers used it to avoid modern authentication defenses like MFA prompts and conditional access policies. The campaign, dubbed LSHIY, highlights risks of legacy OAuth flows remaining enabled, and researchers recommend disabling ROPC grants where possible.